logo

How Memory Forensics Revealed Exploitation of Ivanti Connect Secure VPN Zero-Day Vulnerabilities

ID: 1ccf4ddb-ebb2-5023-a3dd-18ea0ded75b4

STIX ID: report--1ccf4ddb-ebb2-5023-a3dd-18ea0ded75b4

Feed Name: Volexity Blog

Threat Score
90/100

Date Published: 2024-02-01

Date Updated: 2026-05-01

...
...

Volexity details how memory forensics enabled them to reconstruct an active exploitation chain of two zero-day vulnerabilities in Ivanti Connect Secure VPN appliances, revealing memory-only POST payloads, base64-encoded commands, attacker-controlled SSH connect-back shells running as root, and evidence that attackers modified the device's Integrity Checking Tool to evade detection; the report emphasizes rapid memory acquisition and automated IOCs to detect and investigate compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.